NG Solution Team
Cybersecurity

Citrix NetScaler: urgent update fixes critical SAML memory overflow

Citrix has released updated NetScaler builds to patch a critical memory-overflow vulnerability (CVE-2026-107406, CVSS4 9.5) that affects devices with SAML functions and is urging administrators to install the updates as soon as possible.

How Citrix NetScaler instances are affected

According to a Citrix security advisory and a company blog post, the flaw is a memory overflow that can allow execution of injected malicious code or cause a denial of service; Citrix rates the risk as “critical.” The advisory says devices with SAML functions enabled are vulnerable. Citrix also references the vulnerability addressed in last weekend’s update, CVE-2026-88779 (CVSS4 8.7, risk “high”).

For NetScaler versions 14.1-73.37 or 13.1-64.23 and later — including the updates released last weekend — only devices configured as SAML identity providers (IdPs) are affected. In older versions, devices acting as SAML service providers (SPs) are also vulnerable.

Administrators can verify whether an instance is configured as a SAML provider by checking its configuration for entries such as “add authentication samlAction” or “add authentication samlIdPProfile.”

Fixed NetScaler versions and mitigation

Citrix says the following versions and newer fixes the security-relevant errors: Citrix NetScaler ADC and Citrix NetScaler Gateway 14.1-73.46 and 13.1-64.29; NetScaler ADC 14.1-FIPS 14.1-73.46 FIPS; and NetScaler ADC 13.1-FIPS and 13.1-NDcPP 13.1-37.283. Even organizations that do not currently use SAML are advised to install the updates to reduce attack surface and to be prepared for configuration changes that might expose the vulnerability in older releases.

Because cybercriminals have been rapidly exploiting Citrix vulnerabilities, Citrix recommends a swift update. The company reports no known attacks exploiting this new vulnerability at the time of publication.

Related posts

Zimbra exploit: did a Russian group steal sensitive data?

David Jones

Microsoft Patch Tuesday: 421 Fixes Include Active Zero-Day

James Smith

LegacyHive: Microsoft issues August patches for Windows zero-day

Jessica Williams

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy